University of Information Technologies and Management
Computer Engineering (Design of Computer Systems, Design of Practical Software, Information and Multimedia Technologies)
About the programme
|
I. The content of science The goal of teaching science is to help students become more professional. The goal is to develop knowledge, skills, and competencies in solving issues related to ensuring the cybersecurity of information systems and information resources. The task of the subject is to familiarize students with the basic concepts of cybersecurity, the basics of cryptography, access control, effective methods and tools for ensuring network and computer security, as well as threats to information security and combating them. |
|
II. Main theoretical part (lectures) II.I. The subject includes the following topics: Section 1 Cybersecurity Lecture 1. Basic concepts of cybersecurity i. Examples of information security in real life, cybersecurity, information security, confidentiality, integrity, usability, risk, thinking like an attacker, systems thinking, asset, threat, vulnerability, control tool, knowledge areas of cybersecurity. Lecture 2 Cybercrime, cyberlaws and cyberethics. Domestic cybercrimes. external cybercrimes, cyberlaws, national laws, international cyberlaws, cyberethics. Lecture 3. Safety of human activities. Human factor in cybersecurity, social engineering , phishing, social engineering protection measures . Section 2. Cybersecurity architecture, strategy, and policy Lecture 4. Cybersecurity architecture, strategy, and policy. Cybersecurity architecture, strategy. Cybersecurity policy and its implementation: information security policy, necessity of security policy, benefits of security policy, hierarchy of security policy, features of security policy , types of information security policy. Section 3. Cryptographic Protection of Information. Lecture 5. Basic concepts of cryptography. Basic terms, sections of cryptography, cryptosystems, Kerckhoff's principles, history of cryptography, cryptographic reflection. Lecture 6. Symmetric cryptographic algorithms and public-key cryptosystems. Stream symmetric encryption algorithms, A5/1 Stream encryption algorithms, block symmetric encryption algorithms, problems in symmetric cryptosystems, One-way function, Factorization problem, modular arithmetic, RSA algorithms, Use of public-key cryptosystems, Key length in public-key cryptosystems. 7. Methods for ensuring data integrity. Hash function, message authentication code, data integrity verification based on hash functions, data integrity verification and anti-repudiation protection based on public-key encryption algorithms, EDS formation process, EDS verification process, public key infrastructure Lecture 8. Disk and file encryption. Methods for secure data deletion. Hardware-software encryption, hardware encryption, software encryption, disk and file system level encryption. Methods for destroying paper documents, destruction of electronic documents. Section 4 Usage Control Lecture 9. Identification and authentication tools. Identification, authentication and authorization, one-way and two-way authentication, multi-factor authentication, password systems, electronic devices, biometric systems. Topic 10. Logical management of data usage. Access control, Discretionary access control (DAC), Mandatory access control (MAC), Role-based access control (RBAC), Attribute-based access control (ABAC), access control matrix, ACL or S-list. Topic 11. Multi-layered security models. Bell-LaPadula model, Biba model, logical and physical access control. Topic 12. Physical protection of data. Physical security, its necessity, factors affecting physical security, natural threats, man-made threats, physical security control, other physical security measures, awareness/training. Section 5. Network Security. Topic 13. Computer networks and network security issues. Network types, network topologies, OSI model, network requirements, TCP/IP model, network tools. Vulnerability, threat, attack, internal threat, external threat, reconnaissance attacks, intrusion attacks, malicious attacks, Denial of service (DOS) attacks. Topic 14. Tools for ensuring network security. Network firewalls, virtual private networks, intrusion detection systems (IDS), data leakage prevention systems (DLP), honeypots. Topic 15. Wireless network security. Types of wireless networks, vulnerabilities in wireless networks, uncontrolled area, unauthorized intrusion, eavesdropping, denial of service, man-in-the-middle attack, rogue network access points (malicious twin attack), Roaming problem, encryption of data transmitted over the network. Topic 16. Risk management. Risk, risk level, risk frequency, risk matrix, risk management, key risk indicators, risk management stages, risk management framework in an organization, risk management information systems (Risk Management Information Systems, RMIS). Section 6. Methods for ensuring usability. Topic 17. Usability concept: backup, data recovery, and event logging. Usability, backup, backup tools. RAID technology, advantages and disadvantages, backup methods, types of backup. Data recovery, causes of data loss, data recovery tools, event logging, types of events in Windows OS. Section 7. Security in software tools Topic 18. Security issues in software tools. Security issues related to websites, common web vulnerabilities, secure and insecure programming languages, concepts of vulnerabilities in software tools, defects, bugs, memory overflows. Topic 19. Computer viruses and virus protection issues. Types of malicious programs, viruses and their classification, functions performed by viruses, methods and tools for detecting malicious software. Section 8 Special Section Topic 20. Record protection. Protecting information related to the record, protecting information with the party you are communicating with, protecting information with parties you are not communicating with. Passwords, password generation, password management, password storage, password transfer, identifying alternative methods to passwords. Topic 21. Protection against social engineering. Types of social engineering, principles used by social engineering professionals, not sharing information on social networks, identifying fake social media connections, using secure software tools. III. Practical training instructions and recommendations The following topics are recommended for practical training .
Practical training should be conducted in an auditorium equipped with multimedia devices by one professor-teacher per academic year. It is appropriate to conduct training using active and interactive methods, and to use appropriate pedagogical and information technologies, respectively. IV. Independent learning and independent work The main goal of independent work assigned to a student is to form and develop knowledge and skills to independently complete specific educational tasks under the guidance and supervision of a teacher. Recommended topics for independent study :
19. Cybercrime and the reasons for its prevalence. 20. Facial image-based authentication method and its features. 21 Fingerprint-based authentication method and its features. 22. Electronic digital signature and the status of its implementation in our republic. 23. Categories of specialists in the field of cybersecurity. 24. Explore career paths in cybersecurity. 25. Starting a career in information security. 26. Popular certifications in cybersecurity. 27. Password management systems (e.g. LastPass) and their use. 28. Virtual private network and its practical use (for example, CyberGhost or ExpressVPN) . 29. What is social engineering and its modern methods? 30. Using the ESET NOD32 antivirus tool. 31. Kaspersky antivirus tool and its use. 32. Install and configure a network security tool (e.g. ZoneAlarm). 33. Virtual private network and its practical use (for example, CyberGhost or ExpressVPN). 34. Configuring user accounts (in particular, password usage policies) in Windows OS . 35. Performing Backup and Restore in Windows OS . 36. Types of privileges in Windows OS, access control procedure for files and directories. 37. Types of privileges in Linux OS, access control procedure for files and directories. 38. Data recovery tools (such as Recuva or EaseUS Data Recovery Wizard Pro) and how to recover data using them. 39. Protect data using the VeraCrypt software tool. It is recommended that students prepare independent work on topics that are to be mastered independently, present it, and perform it in practice. V. Learning outcomes (Developed competencies) As a result of mastering the subject, the student will:
VI. Educational technologies and methods
VII. Requirements for obtaining loans: Fully master the theoretical and practical concepts of the subject, be able to fully reflect the results of the analysis, conduct independent observations of the processes being studied, complete the tasks and assignments given in the forms of current and intermediate control, and submit the final control work (regardless of its type). Main literature
Additional literature
Internet resource bee 1. https://cryptomuseum.com/crypto/index.htm 2. https://www.futurelearn.com/courses/cryptography 3. https://www.edx.org/learn/cryptography 4. https://classcentral.com/course/crypto-616 5.https://medium.com/privacy-preserving-natural-language-processing/homomorphic-encryption-for-beginners-a-practical-guide-part-1-b8f26d03a98a. |
Similar programmes
Webster University in Tashkent
Management Information Systems
62 937 500 so'm
per year
Университет Пучон в городе Ташкент
e-Business
35 356 800 so'm
per year
Tashkent university of information technologies named after Muhammad al-Khwarizmi
Information and communication technologies
—
Diplomat University
Information and communication technologies
24 000 000 so'm
per year
Samarkand State University named after Sharof Rashidov
Information Security
11 040 000 so'm
per year
Tashkent International University of Financial Management and Technologies
Artificial Intelligence
20 000 000 so'm
per year